Massive Breach Exposes Keyboard App that Collects Personal Data On Its 31 Million Users

Haythem Elmir
0 1
Read Time1 Minute, 24 Second

In the digital age, one of the most popular sayings is—if you’re not paying, then you’re not the customer, you’re the product.

While downloading apps on their smartphones, most users may not realize how much data they collect on you.

Believe me; it’s way more than you can imagine.

Nowadays, many app developers are following irresponsible practices that are worth understanding, and we don’t have a better example than this newly-reported incident about a virtual keyboard app.

A team of security researchers at the Kromtech Security Center has discovered a massive trove of personal data belonging to more than 31 million users of the popular virtual keyboard app, AI.type, accidentally leaked online for anyone to download without requiring any password.
Founded in 2010, Ai.type is a customizable and personalizable on-screen keyboard for mobile phones and tablets, with more than 40 million users worldwide.

Apparently, a misconfigured MongoDB database, owned by the Tel Aviv-based startup AI.type, exposed their entire 577 GB of the database online that includes a shocking amount of sensitive details on their users, which is not even necessary for the app to work.

« …they appear to collect everything from contacts to keystrokes. »

The leaked database of over 31 million users includes:

  • Full name, phone number, and email address
  • Device name, screen resolution and model details
  • Android version, IMSI number, and IMEI number
  • Mobile network name, country of residence and even user enabled languages
  • IP address (if available), along with GPS location (longitude/latitude).
  • Links and the information associated with the social media profiles, including birth date, emails, photos.

To read the original article:

https://thehackernews.com/2017/12/keyboard-data-breach.html

Happy
Happy
0 %
Sad
Sad
0 %
Excited
Excited
0 %
Sleepy
Sleepy
0 %
Angry
Angry
0 %
Surprise
Surprise
100 %

Average Rating

5 Star
0%
4 Star
0%
3 Star
0%
2 Star
0%
1 Star
0%

Laisser un commentaire

Next Post

FAME : An Open-Source Malware Analysis Framework

FAME is a recursive acronym meaning “FAME Automates Malware Evaluation”. It is meant to facilitate analysis of malicious files, leveraging as much knowledge as possible in order to speed up and automate end-to-end analysis. Best case scenario: the analyst drops a sample, waits for a few minutes, and FAME is […]